Early adoption left gaps in security, compliance, and validated systems
The client — a large international healthcare provider — had been using Microsoft 365 for some time. As an early adopter, they understood that initial configurations may not have kept pace with evolving regulatory requirements and internal standards.
Their concerns centred on three areas: security posture, regulatory compliance (including GDPR across EU operations), and systems validation under GxP guidelines — a critical requirement in the pharmaceutical and healthcare industries.
"They needed clarity: were their Microsoft 365 policies actually protecting the business, meeting regional requirements, and satisfying validation standards?"
Additionally, they wanted to establish both local and global policies to address regional regulatory differences — ensuring a consistent and defensible approach across their international footprint.
A structured Health Check across the full Microsoft 365 estate
Cordapse worked closely with the client to ensure the Health Check was tightly scoped and focused on the areas that mattered most. Rather than a broad-brush review, we structured our assessment around three pillars and four key applications.
From assessment to a clear, actionable report
Cordapse delivered a comprehensive Microsoft 365 Health Check Report that gave the client a clear picture of their current position — and a structured path to remediation.
- Engaged stakeholders across IT, compliance, and operations to understand the organisation's regulatory obligations and risk appetite.
- Mapped all Microsoft 365 applications in active use and defined the assessment boundaries across the global tenant.
- Reviewed security configurations across Exchange, Teams, SharePoint, and OneDrive — including identity, access controls, and data protection settings.
- Evaluated tenant policies against GxP systems validation requirements and relevant ISO standards.
- Identified gaps in GDPR compliance at both global and regional levels, with particular focus on EU data handling obligations.
- Designed local and global policy frameworks to meet regional regulatory requirements while maintaining operational consistency across the international estate.
- Recommended a prioritised remediation roadmap to address identified risks in a structured, manageable sequence.
- Delivered a detailed Health Check Report presenting findings, risk ratings, and specific recommendations for each area assessed.
- Presented outcomes to senior stakeholders, providing the assurance they needed to move forward with confidence.